required text

required text


When you use the field extractor to create custom fields, you can specify required text to improve the accuracy of the field extraction. The regular expression created for this extraction ensures that field values are extracted only from events that contain the required text string.

For example, if you use the field extractor to create a field extraction for candidate_name and candidate_id fields with the required text "Department H," then Splunk Enterprise extracts only candidate_name and candidate_id values from fields that contain the string "Department H."

For more information

In the Knowledge Manager Manual: